A reflected cross-site scripting vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.”
View the template here CVE-2021-35265.yaml
References:
https://github.com/ARPSyndicate/cvemon